312-50V13 · Question #259
Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to…
The correct answer is A. Quid pro quo. Explanation Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a "service" (technical support/warning about a server compromise) in return for the victim's compliance (executing commands and installing malicious files) - a classic…
Question
Options
- AQuid pro quo
- BDiversion theft
- CElicitation
- DPhishing
How the community answered
(31 responses)- A84% (26)
- B3% (1)
- C10% (3)
- D3% (1)
Explanation
Explanation
Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a "service" (technical support/warning about a server compromise) in return for the victim's compliance (executing commands and installing malicious files) - a classic "something for something" social engineering trade-off where the attacker poses as a helpful technical resource to gain access.
Why the distractors are wrong:
- B (Diversion theft) involves tricking a courier or delivery person into delivering goods to the wrong location - it's physically oriented and doesn't match this scenario.
- C (Elicitation) is about subtly extracting information through casual conversation without raising suspicion, not impersonating support staff to issue instructions.
- D (Phishing) is conducted via email or fake websites, not through phone calls (phone-based attacks are specifically "vishing," a subset distinct from phishing).
Memory Tip
Think of quid pro quo as "I'll scratch your back if you scratch mine" - the attacker always offers something (help, support, a warning) in exchange for compliance or access. If the scenario involves a fake service offer over the phone leading to a trade-off action, think quid pro quo.
Topics
Community Discussion
No community discussion yet for this question.